WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 751–800 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 29
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Internal Links Manager Plugin seo-automated-link-building Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24679 Patchstack
8.5 High Form Builder CP Plugin cp-easy-form-builder SQL Injection ≤ 1.2.41 Fixed in 1.2.42 CVE-2025-24672 Patchstack
5.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24633 Patchstack
6.5 Medium Form Builder CP Plugin cp-easy-form-builder SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.41 CVE-2024-13680 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets ≤ 3.11.11 CVE-2024-12477 Wordfence
6.1 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.6.5 CVE-2024-13319 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-22716 Patchstack
6.4 Medium Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.31 CVE-2024-13393 Wordfence
6.1 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.5 CVE-2024-13516 Wordfence
6.5 Medium GMAPS for WPBakery Page Builder Free Plugin gmaps-for-visual-composer-free Cross-Site Scripting ≤ 1.2 CVE-2025-23775 Patchstack
4.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-22731 Patchstack
6.5 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Scripting Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) ≤ 1.27.5 Fixed in 1.27.6 CVE-2025-22759 Patchstack
4.3 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup ≤ 1.13.10 CVE-2024-13215 Wordfence
6.4 Medium PDF for WPForms + Drag and Drop Template Builder Plugin pdf-for-wpforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yeepdf_dotab Shortcode ≤ 4.6.0 CVE-2024-12593 Wordfence
6.4 Medium Page Builder by SiteOrigin Plugin siteorigin-panels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter ≤ 2.31.0 CVE-2024-12240 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link ≤ 3.4.2 CVE-2024-12304 Wordfence
7.1 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-22295 Patchstack
6.5 Medium Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail Plugin yeemail Cross-Site Scripting ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-22802 Patchstack
6.5 Medium Content Blocks Builder Plugin content-blocks-builder Cross-Site Scripting ≤ 2.7.6 Fixed in 2.7.7 CVE-2025-22810 Patchstack
6.4 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Broken Access Control animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross-Site Scripting ≤ 9.0.0 CVE-2024-6155 Wordfence
8.8 High SKT Page Builder Plugin skt-builder Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.7 CVE-2024-12848 Wordfence
4.3 Medium Header Builder Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Header Deletion No login needed ≤ 1.3.8 CVE-2024-12206 Wordfence
7.5 High Cost Calculator Builder PRO Plugin SQL Injection Unauthenticated SQL Injection via data No login needed ≤ 3.2.15 CVE-2024-11939 Wordfence
4.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 5.1.0 CVE-2024-12045 Wordfence
6.4 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.8.8 CVE-2024-12112 Wordfence
5.3 Medium SureForms – Drag and Drop Form Builder Plugin sureforms Broken Access Control Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure No login needed ≤ 1.2.2 CVE-2024-12713 Wordfence
5.3 Medium Saoshyant Page Builder Plugin saoshyant-page-builder Broken Access Control No login needed ≤ 3.8 CVE-2025-22560 Patchstack
6.1 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.12.9 CVE-2024-12738 Wordfence
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2024-49649 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2024-56285 Patchstack
7.5 High Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Local File Inclusion WPBakery Page Builder plugin <= 3.0 - Local File Inclusion ≤ 3.0 Fixed in 3.1 CVE-2024-56286 Patchstack
5.9 Medium Pretty Simple Popup Builder Plugin pretty-simple-popup-builder Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.0.10 CVE-2024-56298 Patchstack
5.9 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5.1 Fixed in 1.6 CVE-2025-22316 Patchstack
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
6.4 Medium Taskbuilder – WordPress Project & Task Management Plugin taskbuilder Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode ≤ 3.0.6 CVE-2024-11930 Wordfence
5.4 Medium 10Web Map Builder for Google Maps Plugin wd-google-maps Broken Access Control Notice Dismissal ≤ 1.0.73 Fixed in 1.0.74 CVE-2023-45272 Patchstack
4.3 Medium ApplyOnline – Application Form Builder and Manager Plugin apply-online Broken Access Control Application Form Builder and Manager plugin <= 2.5.3 - Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2023-46080 Patchstack
6.5 Medium Kali Forms Plugin kali-forms Broken Access Control ≤ 2.3.28 Fixed in 2.3.29 CVE-2023-45275 Patchstack
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Broken Access Control MightyForms plugin <= 1.3.9 - Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2024-56002 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Local File Inclusion ≤ 7.6.3 Fixed in 7.6.5 CVE-2024-56216 Patchstack
6.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Arbitrary Shortcode Execution The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.8.22 CVE-2024-12238 Wordfence
4.9 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection Authenticated (Admin+) SQL Injection ≤ 8.7.15 CVE-2024-10862 Wordfence
4.3 Medium Avada Builder Plugin Information Disclosure Authenticated (Contributor+) Protected Post Disclosure ≤ 3.11.12 CVE-2024-12335 Wordfence
7.5 High WP Data Access – App, Table, Form and Chart Builder Plugin wp-data-access SQL Injection App, Table, Form and Chart Builder plugin <= 5.5.22 - Unauthenticated SQL Injection No login needed ≤ 5.5.22 CVE-2024-12428 Wordfence
4.3 Medium Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure ≤ 2.17.3 CVE-2024-12190 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget ≤ 1.6.46 CVE-2024-11230 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings ≤ 3.25.9 CVE-2024-10453 Wordfence
6.5 Medium Fusion Plugin fusion Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37962 Patchstack
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only